Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Technology

Researchers Demonstrate Coin-Sized Device That Can Hijack Boeing 737 Autopilot

A team from UC San Diego and Oberlin College unveiled a sub-$100, coin-sized gadget that can infiltrate a Boeing 737’s autopilot by plugging into an external port, potentially altering flight data without pilots noticing.

Researchers from the University of California at San Diego and Oberlin College have created a Wi-Fi-enabled, coin-sized device costing less than $100 that can commandeer a Boeing 737’s autopilot by exploiting an externally reachable port typically used for maintenance. In less than a minute the implant can be inserted, then transmit electrical signals that overwrite commands to the flight-management computer and the multipurpose control display, allowing attackers to falsify critical data such as aircraft weight, outside temperature or navigation waypoints while showing false readings to pilots.

The technique, dubbed “Bus Driver,” was validated on a laboratory test bed and later demonstrated inside a Boeing facility, after the team spent over a decade acquiring and assembling spare avionics components. Boeing reviewed the findings and maintains that layered protections reduce the likelihood of a successful real-world attack, though it has not disclosed any immediate hardware fix. The researchers argue that, without redesign, the flaw could remain exploitable for years and recommend sealing or removing the vulnerable connector, or upgrading software defenses with authentication and isolation measures. They stress that the discovery highlights a broader need to rethink physical-access threat models for critical aviation systems.

Why it matters

It shows that a cheap, easily hidden device could let attackers manipulate a commercial jet’s flight controls from the ground.

In this story

physical access hackingBoeing 737autopilot takeovercoin-sized devicebus driver attackaviation cybersecurity